The P.R.I.S.M.
Welcome,
Guest
. Please
login
or
register
.
Did you miss your
activation email?
February 08, 2010, 06:07:15 PM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
Search:
Advanced search
Borderlands/SecuROM is an Epic Fail
Project RYG's - Essential Documents
Reclaim Your Game - Site
Know Your Game - Wiki
48528
Posts in
3821
Topics by
753
Members
Latest Member:
ForumTeam_support
The P.R.I.S.M.
Companies Using Invasive DRM
EA Games
Sims Series
TSR TOOL NEAT & CLEAN: Version 6.4
« previous
next »
Pages:
1
2
[
3
]
4
Author
Topic: TSR TOOL NEAT & CLEAN: Version 6.4 (Read 2455 times)
JohanTSR
The Prism Collective
Posts: 5
Re: TSR Installs SPYWARE! (at least has the chance to do so)
«
Reply #30 on:
July 24, 2009, 05:49:37 PM »
Hello,
My name is Johan Isacsson and i'm one of the programmers working with this application you are discussing.
I'm also one of the original founders of TSR.
Thomas brought this thread to my attention, if you have any technical questions about what the program does i'm happy to answer them.
As for the library injection thing, i don't know what causes that warning but we rely on some external DLL's which i suspect might cause this (SlimDX or Smart Property Grid most likely), do you have any more details on that warning? Does it happen when you install the program or when you launch the app?
What do you mean by adding itself to the registry at startup, is it during install or when running the app you mean?
If it's the installer well that's the way our installation software does it, we pretty much used the defaults (Advancedinstaller).
The actual application shouldn't add anything to the registry at launch, if you claim it does please let me know exactly what it does and i can see if i can find something that could cause it.
Yes we load 4 images and an XML document when the welcome screen is displayed. We don't add any own information to the http requests headers or anything like that and we use the standard .net stuff
to do it. Is that called phone home? I though that meant sending off information, not just loading data from the net.
If someone modifies the program or any other program for that matter and manages to distribute it they have the potential to do a lot of bad things, i don't think our http requests makes it any worse, IMHO.
Regards,
Johan Isacsson
Quote from: Sblade on July 24, 2009, 02:36:04 PM
While I finish the code tests I want to ask Thomas:
Why it does adds itself to the registry at startup without asking permission? (I know Yahoo does the same with its MEssenger and toolbar, but 2 wrongs doesn´t make a right, no matter how big the company is)
I want you to confirm that it phones home at startup, this is so the program can show you the latest subscriber downloads available on TSR. This is a security risk, as anyone who distributes your tool and MODIFIES IT, can infect tons of computers with ease. By default the tool must NOT phone home IMO.
Will be back later
EDIT: I want clarification of this too: 5. NO WARRANTIES
IBIBI HB expressly disclaims any warranty for the SOFTWARE PRODUCT. The SOFTWARE PRODUCT is provided 'As Is' without any express or implied warranty of any kind, including but not limited to any warranties of merchantability, noninfringement, or fitness of a particular purpose. IBIBI HB does not warrant or assume responsibility for the accuracy or completeness of any information, text, graphics, links or other items contained within the SOFTWARE PRODUCT.
IBIBI HB makes no warranties respecting any harm that may be caused by the transmission of a computer virus, worm, time bomb, logic bomb, or other such computer program
. IBIBI HB further expressly disclaims any warranty or representation to Authorized Users or to any third party.
You must guarantee your software is worm free
Logged
ThomasTSR
The Prism Collective
Posts: 14
Re: TSR Installs SPYWARE! (at least has the chance to do so)
«
Reply #31 on:
July 25, 2009, 01:01:58 AM »
In reply to the disclaimer NO WARRANTIES.
While WE guarantee a worm/virus/malware free tool, we can not guarantee that someone does not do as you've suggested and redistribute it containing such things. So this clause is simply there to protect US in case someone is up to such a thing.
Logged
Sblade
Sec. Admin & Starforce DRM/Game Team Leader
Administrator
The Prism Collective
Posts: 1469
Inspector SwitchBlade
Re: TSR DOES NOT Installs SPYWARE! (only phones home)
«
Reply #32 on:
July 25, 2009, 01:35:22 AM »
Quote from: ThomasTSR on July 25, 2009, 01:01:58 AM
In reply to the disclaimer NO WARRANTIES.
While WE guarantee a worm/virus/malware free tool, we can not guarantee that someone does not do as you've suggested and redistribute it containing such things. So this clause is simply there to protect US in case someone is up to such a thing.
Then the disclaimer must put it the way you have said those words. Meaning it is safe iff downloaded from TSR, and unsafe if downloaded from another location. That´s my opinion and I stand by it
Quote from: JohanTSR on July 24, 2009, 05:49:37 PM
Hello,
My name is Johan Isacsson and i'm one of the programmers working with this application you are discussing.
I'm also one of the original founders of TSR.
Thomas brought this thread to my attention, if you have any technical questions about what the program does i'm happy to answer them.
As for the library injection thing, i don't know what causes that warning but we rely on some external DLL's which i suspect might cause this (SlimDX or Smart Property Grid most likely), do you have any more details on that warning? Does it happen when you install the program or when you launch the app?
What do you mean by adding itself to the registry at startup, is it during install or when running the app you mean?
If it's the installer well that's the way our installation software does it, we pretty much used the defaults (Advancedinstaller).
The actual application shouldn't add anything to the registry at launch, if you claim it does please let me know exactly what it does and i can see if i can find something that could cause it.
Yes we load 4 images and an XML document when the welcome screen is displayed. We don't add any own information to the http requests headers or anything like that and we use the standard .net stuff
to do it. Is that called phone home? I though that meant sending off information, not just loading data from the net.
If someone modifies the program or any other program for that matter and manages to distribute it they have the potential to do a lot of bad things, i don't think our http requests makes it any worse, IMHO.
Regards,
Johan Isacsson
The warning might be due that it modifies some DLL´s after creating it. But they are their OWN DLLs. In the preliminary tests I have found 0 dangerous objects. The only discussable thing that the tool does is phoning home which it comes to tastes, and should be safe AS LONG AS YOU DOWNLOAD IT FROM TSR. It is strongly advised NOT TO get it from another location.
I´m closing this down and editing the title. If anyone wants me to re-open the discussion I would need.
a)proof it has been DL´ed from TSR
b) Screenshot and DETAILS (not like the old man PEscado) from at least 2 different AV/Antispyware applications
c) instructions of reproducing the output.
I publicly apologize Thomas and The Sims Resource for the initial inconsistent report, which came from a long trusted source. Which from now on, will no longer be trusted.
Regards
Sblade
LOCKDOWN
EDIT: Will be open till ThomasTSR posts. Will be relocked after. All other posts will be removed
«
Last Edit: July 25, 2009, 02:06:47 AM by Sblade
»
Logged
Long live on our hearts the King of POP
ThomasTSR
The Prism Collective
Posts: 14
Re: TSR DOES NOT Installs SPYWARE! (only phones home)
«
Reply #33 on:
July 25, 2009, 02:48:23 AM »
Thank you Sblade for your investigation - we appreciate it very much!
We will update the EULA accordingly in the next release of the tool (which happens almost daily with smaller bugfixes).
Hats off to you and your team.
Logged
Sblade
Sec. Admin & Starforce DRM/Game Team Leader
Administrator
The Prism Collective
Posts: 1469
Inspector SwitchBlade
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #34 on:
August 02, 2009, 08:55:39 AM »
Hi there Thomas.
I have been able to reproduce the Library Injection output in a CLEAN vmware machine.
The first warning about the tool to launch at Windows startup is nothing out of the ordinary, might be done for reducing load times to simmers. This is the reason the first warning screenshot is NOT the reason I reopened the thread.
The second warning is just unnaceptable. Click on the attach to see.
A library program that is automatically loaded AT STARTUP and by some or ALL applications seems like a NO NO for me.
Tested on:
TSR installer 0.6.1.0
Vmware 6.5 build 156735
Inside the VMware Machine: Trend Micro Internet Security Pro 2009
I´m going to try some other AV applications, and I hope not to meet the warning anymore. Meanwhile, that warning is enough for me to reopen the thread
2ndwarningHighSecurityRiskdetailssmall.JPG
(127.97 KB, 1014x741 - viewed 35 times.)
Logged
Long live on our hearts the King of POP
Calipip4
Champion of Virtue
Administrator
The Prism Collective
Posts: 4844
aka Lisa
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #35 on:
August 02, 2009, 09:30:27 AM »
Thanks for the headsup Blade.
If that's from the older tool.... I'd like to see the results of the newer tool too.... and I'd like it tested with other AV's and Malware blockers if possible.
Logged
Nasty DRM's
Sblade
Sec. Admin & Starforce DRM/Game Team Leader
Administrator
The Prism Collective
Posts: 1469
Inspector SwitchBlade
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #36 on:
August 02, 2009, 09:34:50 AM »
Quote from: Calipip4 on August 02, 2009, 09:30:27 AM
Thanks for the headsup Blade.
If that's from the older tool.... I'd like to see the results of the newer tool too.... and I'd like it tested with other AV's and Malware blockers if possible.
Tested and downloaded NOW just from TST. Version 6.3.0 same warnings
The warning means it is modifying a program or VARIOUS programs. By modifying a program´s extension, you can modify a program behaviour entirely
That thread added to the Windows Startup we got in the first warning.... seems like a trojan horse behaviour even if the code is safe.
firstwarningdetails.JPG
(127.75 KB, 965x809 - viewed 34 times.)
«
Last Edit: August 02, 2009, 09:48:24 AM by Sblade
»
Logged
Long live on our hearts the King of POP
DarkRaven
Avatar Queen & DRM/Game Tester
Administrator
The Prism Collective
Posts: 1904
aka Roxy
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #37 on:
August 02, 2009, 09:48:13 AM »
That error doesn't sound good. Thanks for testing things Blade.
Logged
evlncrn8
Tech Staff
The Prism Collective
Posts: 24
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #38 on:
August 02, 2009, 09:59:36 AM »
@Thomas, the dll injection i can only suspect is done via appinit_dlls, to make a global hook in all processes (user32.dll uses this registry key to subload other dlls when user32.dll is loaded), would i be right ?
Logged
Calipip4
Champion of Virtue
Administrator
The Prism Collective
Posts: 4844
aka Lisa
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #39 on:
August 02, 2009, 11:06:50 AM »
Thanks for doing the extra testing Blade.
This isn't looking good to me at all
For those that need more info on what Blade is talking about... use this link -
http://en.wikipedia.org/wiki/DLL_injection
Logged
Nasty DRM's
KarenSlayer
Retired Prism Welcomer
Retired Staff
The Prism Collective
Posts: 1429
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #40 on:
August 02, 2009, 11:16:14 AM »
Im with the rest thanks blade for testing it
lov kazz
Logged
midfingr
P.R.I.S.M. Admin & DRM/Game Tester
Administrator
The Prism Collective
Posts: 2680
KING of SecuROM Removal
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #41 on:
August 02, 2009, 12:54:46 PM »
Err, um, from the picture.. it's alerting you that the program is adding itself to the start up entry (i.e. start menu item, registry or service). I dislike that kind of stuff, but it's nothing out of the ordinary. So, the security app is giving you a choice as to whether you want it starting up with Windows or not.
Logged
My PC Game Collection
Sblade
Sec. Admin & Starforce DRM/Game Team Leader
Administrator
The Prism Collective
Posts: 1469
Inspector SwitchBlade
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #42 on:
August 02, 2009, 01:35:26 PM »
Mid check the DLL injection thing buddy. As for the ones who would like to blame Trend Micro.
Global trap? Interesting....
Tested on VMware clean machine again Kaspersky Internet Security 2010 9.0.0.463 Same os
I have the startup screen too. I´ll upload it later
Kaspersky7thwarningHIGHSECURITYRISK.JPG
(115.68 KB, 1152x619 - viewed 32 times.)
Logged
Long live on our hearts the King of POP
midfingr
P.R.I.S.M. Admin & DRM/Game Tester
Administrator
The Prism Collective
Posts: 2680
KING of SecuROM Removal
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #43 on:
August 02, 2009, 02:33:58 PM »
Thanks Blade
That's a little more intriguing. It's hard to say looking at a screenshot. However, DLL injection could just mean code, used to alter game files, which I imagine what this program is meant for. What happens if you disallow all of these alerts? Does the program still function? Maybe you can pin-point something that shouldn't be there.
Kaspersky Internet Security, while good, drove me looney toones when installing programs. I would look at a separate system intrusion utility to counter (of course without Kaspersky) as it tends to be very aggressive with other security software such as Spybot S & D.
Logged
My PC Game Collection
Darklord
DRM/Game Tester
Prism Regulars
The Prism Collective
Posts: 390
Re: TSR TOOL HIGH SECURITY RISK REPRODUCED WITH VMWARE
«
Reply #44 on:
August 02, 2009, 02:46:40 PM »
I agree with mid that this program alerts are normal for that kind of program and there's no particular evidence for malware or spyware being resident in TSR tools.
I think that dll-injection thingy can happen when an item is added to the context menu.
Also think about how TSR tools works. It's an editor that is used to change files. That's always suspicious behaviour for antivirus software or firewalls. I think we should calm down on this.
So, I won't install that prog cause I see no use for it, for now.
Logged
Pages:
1
2
[
3
]
4
« previous
next »
Jump to:
Please select a destination:
-----------------------------
Prism Headquarters
-----------------------------
=> Site Announcements
===> RYG Updates
=> Public Chamber
-----------------------------
PROJECT RYG - RYG's DRM TESTING PROGRAM
-----------------------------
=> Essential Documents
===> Questions and Comments
=> Project RYG's DRM Reports
=> RYG-Approved DRM & DRM-Approved Games
=> Interviews With RYG
-----------------------------
Companies Using Invasive DRM
-----------------------------
=> EA Games
===> Sims Series
===> Spore
===> Bioware
===> Crysis Warhead
===> Red Alert 3
=> Ubisoft
=> Other
===> Activision Blizzard
===> Atari
===> Bethesda
===> Codemasters
===> Sony
===> Microtransaction
-----------------------------
DRM-Free and loving it.
-----------------------------
=> These AREN'T infected!
-----------------------------
PC Maintenance, Driver Updates and other Fun Things
-----------------------------
=> PC Maintenance Tutorials
=> Driver Updates
=> Show Us Your Computer
=> The other Fun Things
-----------------------------
Securom Community Issues, News and Petitions
-----------------------------
=> The Community Campaign
=> The Petition/Letters Campaigns
=> Securom Useful Links
Loading...